CVE-2026-35533

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:jdx:mise:*:*:*:*:*:rust:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) mise gestiona herramientas de desarrollo como node, python, cmake y terraform. Desde el 2026.2.18 hasta el 2026.4.5, mise carga la configuración de control de confianza de un archivo .mise.toml de proyecto local antes de que se ejecute la verificación de confianza. Un atacante que puede colocar un .mise.toml malicioso en un repositorio puede hacer que ese mismo archivo parezca de confianza y luego alcanzar directivas peligrosas como [env] _.source, templates, hooks o tasks.

17 Jun 2026, 10:40

Type Values Removed Values Added
References () https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 - Vendor Advisory, Exploit () https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 - Exploit, Vendor Advisory

15 Apr 2026, 20:33

Type Values Removed Values Added
References () https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 - () https://github.com/jdx/mise/security/advisories/GHSA-436v-8fw5-4mj8 - Vendor Advisory, Exploit
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:jdx:mise:*:*:*:*:*:rust:*:*
First Time Jdx
Jdx mise

07 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 21:17

Updated : 2026-07-24 21:10


NVD link : CVE-2026-35533

Mitre link : CVE-2026-35533

CVE.ORG link : CVE-2026-35533


JSON object : View

Products Affected

jdx

  • mise
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo